Audit History
agile-planning - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 6, 2026, 02:27 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 02:27 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 29, 2026, 11:24 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 23, 2026, 02:15 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 02:27 PM
All six static findings are false positives after contextual review. The flagged external command patterns are markdown code fences and examples, and the reconnaissance flag points to task-writing guidance.
Risk Factors
⚙️ External commands (5)
Jul 6, 2026, 02:27 PM
All six static findings are false positives after contextual review. The flagged external command patterns are markdown code fences and examples, and the reconnaissance flag points to task-writing guidance.
Risk Factors
⚙️ External commands (5)
Jun 29, 2026, 11:24 PM
Static analysis reported command execution, weak cryptography, and reconnaissance patterns, but review found markdown planning examples rather than executable code. No prompt injection, network access, filesystem access, secret handling, or malicious intent was found in SKILL.md, references/sprint-guide.md, or references/template.md.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 23, 2026, 02:15 AM
This skill is a pure documentation resource containing agile planning templates and best practices. All 85 static findings are false positives: markdown backticks for code formatting (not shell execution), documentation metadata (not cryptographic code), and metadata terminology (not reconnaissance). No executable code, network access, or file system operations exist in this skill.